Fakecalls

MITRE ATT&CK: S1080 View on attack.mitre.org

Aliases: Fakecalls

First seen
2021-01-01 00:00:00
Malware type
trojan, spyware
Family
Malware family
Operating systems
android
Related IoCs
13 (9 malicious)
Last IoC activity
2026-07-31 15:41:28
Profile updated
2026-07-07 14:06:09

Targeted industries: financial-services

Targeted regions: country_code:kr

Context

Fakecalls is an Android trojan, first detected in January 2021, that masquerades as South Korean banking apps. It has capabilities to intercept calls to banking institutions and even maintain realistic dialogues with the victim using pre-recorded audio snippets.

Recent IoC activity

9 malicious indicators in Maltiverse are attributed to Fakecalls (S1080). The 9 most recently updated:

TypeIndicatorUpdatedSources
hostname tewen006.com 2026-06-05 1
hostname allcallpush02.com 2025-10-22 2
hostname allcallpush09.com 2025-10-22 2
hostname chaowen006.com 2025-10-22 2
hostname chaowen000.com 2025-10-22 2
hostname chaowen105.com 2025-10-22 2
hostname wending015.com 2025-10-22 2
hostname allcallpush01.com 2025-10-22 2
file sample kbbank.apk 2025-02-17 2

Malware & tools used

  • Data from Local System (attack-pattern)
  • Call Log (attack-pattern)
  • Video Capture (attack-pattern)
  • Location Tracking (attack-pattern)
  • Contact List (attack-pattern)
  • Audio Capture (attack-pattern)
  • SMS Messages (attack-pattern)
  • Call Control (attack-pattern)
  • Match Legitimate Name or Location (attack-pattern)
  • Exfiltration Over C2 Channel (attack-pattern)
  • File Deletion (attack-pattern)

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Apk.Fakecalls (report)
  • research.checkpoint.com — South Korean Android Banking Menace Fakecalls (report)
  • kaspersky.com.au — 30379 (report)
  • MITRE ATT&CK — S1080 (report)
  • kaspersky.com — 44072 (report)

External references